TEESec: Pre-Silicon Vulnerability Discovery for Trusted Execution Environments
Moein Ghaniyoun, Kristin Barber, Yuan Xiao, Yinqian Zhang, Radu Teodorescu
摘要
Trusted execution environments (TEE) are CPU hardware extensions that provide security guarantees for applications running on untrusted operating systems. The security of TEEs is threatened by a variety of microarchitectural vulnerabilities, which have led to a large number of demonstrated attacks. While various solutions for verifying the correctness and security of TEE designs have been proposed, they generally do not extend to jointly verifying the security of the underlying microarchitecture. This paper presents TEESec, the first pre-silicon framework for discovering microarchitectural vulnerabilities in the context of trusted execution environments. TEESec is designed to jointly and systematically test the TEE and underlying microarchitecture against data and metadata leakage across isolation boundaries. We implement TEESec in the Chipyard framework and evaluate it on two open-source RISC-V out-of-order processors running the Keystone TEE. Using TEESec we uncover 10 distinct vulnerabilities in these processors that violate TEE security principles and could lead to leakage of enclave secrets.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper22
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher 等USENIX Security 2018 · 被引用 1,456 次
- Foreshadow: Extracting the Keys to the Intel SGX Kingdom with Transient Out-of-Order ExecutionJo Van Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin 等USENIX Security 2018 · 被引用 1,175 次
- Sanctum: Minimal Hardware Extensions for Strong Software IsolationVictor Costan, Ilia A. Lebedev, Srinivas DevadasUSENIX Security 2016 · 被引用 649 次
- Inferring Fine-grained Control Flow Inside SGX Enclaves with Branch ShadowingSangho Lee, Ming-Wei Shih, Prasun Gera, Taesoo Kim 等USENIX Security 2017 · 被引用 536 次
- ZombieLoad: Cross-Privilege-Boundary Data SamplingMichael Schwarz, Moritz Lipp, Daniel Moghimi, Jo Van Bulck 等CCS 2019 · 被引用 464 次
相关 Paper
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic 等EuroSys 2020 · 被引用 381 次
- VirTEE: a full backward-compatible TEE with native live migration and secure I/OJianqiang Wang, Pouya Mahmoody, Ferdinand Brasser, Patrick Jauernig 等DAC 2022 · 被引用 11 次
- HyperTEE: A Decoupled TEE Architecture with Secure Enclave ManagementYunkai Bai, Peinan Li, Yubiao Huang, Michael C. Huang 等MICRO 2024 · 被引用 5 次
- Trust-V: Toward Secure and Reliable Storage for Trusted Execution EnvironmentsSeung-Kyun Han, Jiyeon Yang, Jinsoo JangASPLOS 2026
- KingsGuard: Enclave Data Protection Under Real-World TEE VulnerabilitiesSaltanat Firdous Allaqband, Deepanjali S, Rohit Srinivas R G, Devashish Gosain 等CCS 2026
